Siemens has disclosed a critical vulnerability in its SiPass Integrated access control system that could allow unauthenticated remote attackers to trigger a denial-of-service (DoS) condition.
Tracked as CVE-2022-31812, the flaw affects all SiPass Integrated versions prior to V2.95.3.18 and has been patched in a security update released on May 23, 2025.
With CVSS v3.1 and v4.0 base scores of 7.5 and 8.7 respectively, this out-of-bounds read vulnerability poses significant risks to organizations using unpatched systems for physical security operations.
The vulnerability originates from improper memory buffer management in the packet integrity verification process of SiPass Integrated’s server applications.
Specifically, the system fails to validate boundaries when processing incoming network packets, enabling attackers to read data beyond allocated memory buffers.
This out-of-bounds read can destabilize the application, leading to crashes or prolonged unresponsiveness.
Siemens ProductCERT highlighted that exploitation requires no authentication, allowing remote attackers to target exposed systems over networks.
The CVSS v3.1 vector emphasizes its network attack vector, low complexity, and high impact on availability.
The newer CVSS v4.0 score incorporates updated metrics, reflecting heightened concerns about attack automation and operational disruption in industrial environments.
Such flaws are particularly critical in access control systems, where uninterrupted operation is essential for facility security.
Mitigation Strategies and Update Guidance
All deployments running SiPass Integrated versions below V2.95.3.18 are vulnerable.
Siemens has released V2.95.3.18 to address the issue, urging immediate installation via its support portal (reference 109827049). While no direct workarounds exist, the advisory recommends:
- Network segmentation to isolate access control systems from untrusted networks.
- Deployment of next-generation firewalls to filter malicious traffic.
- Implementation of strict access controls to minimize attack surface exposure.
This vulnerability underscores the escalating cybersecurity risks in operational technology (OT) environments, where legacy systems often interface with modern IT infrastructure.
Siemens stresses that these measures complement but do not replace the critical need for patching.
Implications for Industrial Security Practices
Organizations unable to patch immediately should monitor network traffic for anomalous patterns and review system logs for signs of exploitation attempts, such as unexpected service restarts or memory-related errors
The SiPass platform, utilized in critical facilities worldwide, exemplifies the convergence of physical and digital security domains.
Siemens’ coordinated disclosure through its ProductCERT team mirrors industry trends of establishing dedicated cybersecurity response units for industrial control systems.
The involvement of Airbus Security in discovering the flaw highlights the value of cross-sector collaboration in vulnerability research.
Historical parallels include a 2023 credential-spoofing vulnerability in a competing access control system, which similarly stemmed from inadequate input validation.
These incidents collectively emphasize the necessity of regular software updates and comprehensive security audits for physical security infrastructure.
According to the Report, The adoption of CVSS v4.0 scoring provides stakeholders with enhanced risk assessment tools, better capturing the operational impact of vulnerabilities in industrial environments.
For CVE-2022-31812, the higher v4.0 score reflects evolving metrics that prioritize availability impacts and network-based exploitability.
The disclosure of CVE-2022-31812 serves as a stark reminder of vulnerabilities inherent in networked access control solutions.
While Siemens’ prompt patch release mitigates immediate risks, long-term security demands layered defense strategies combining timely updates, network hardening, and continuous monitoring.
As cyber-physical attacks grow in sophistication, organizations must extend cybersecurity rigor to OT systems, ensuring the resilience of both digital and physical security infrastructures.
For ongoing protection, Siemens advises subscribing to ProductCERT advisories and adhering to its General Security Recommendations, including regular system hardening and incident response planning.
Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates.